Hackers Turn 13,000 MikroTik Routers Into Proxy Network for Cybercrime

Hackers Turn 13,000 MikroTik Routers Into Proxy Network for Cybercrime

Attackers are exploiting a critical vulnerability in MikroTik routers that allows them to gain full administrative control without authentication through the internet-accessible SSH service. CERT Polska issued an alert on September 5, 2024, after successful attacks were observed starting at least September 2. The organization dubbed this exploit chain MikroTrick, which appears to involve two separate vulnerabilities working together, though the exact technical details of how they combine to enable unauthenticated admin access have not been publicly disclosed. The number of affected victims and the identity of the attackers remain unknown.

MikroTik has released security patches for multiple RouterOS versions to address these vulnerabilities. According to CERT Polska, users should immediately update their routers and then carefully inspect their configurations for any unauthorized changes made during potential compromise. Home users running default firewall configurations should be protected from public access to management ports, but anyone who has modified these rules may be vulnerable. After applying updates, administrators should review system logs and check device status using specific RouterOS commands to detect signs of compromise.

For those unable to immediately apply patches, CERT recommends several temporary mitigation measures including disabling exposed services or restricting access to trusted management networks only, particularly for SSH, web interfaces, and bandwidth testing services. CERT also advises against initiating TLS connections or using the built-in SSH clients on unpatched devices. Warning signs of compromise include unexpected user accounts with elevated privileges, suspicious scripts or configuration changes, and specific log entries containing the pattern ssh:-2@ in account creation events.

The timeline of this incident raises questions about whether this qualifies as a zero-day attack. MikroTik's beta release notes show a September 2 changelog date with public announcements following on September 3, while attacks were observed starting September 2. This timing suggests patches may not have been publicly available before exploitation began, though this remains unconfirmed. If compromise is detected, CERT urges organizations to preserve all evidence before attempting recovery and to leave any flagged device status in place until investigations conclude. Both CERT Polska and MikroTik have been contacted for additional comment on the incident.

Stay secure — stay Wavasec. 🔐